Business IT projects · Across Québec Request a quoteFrançais

Incident response

Incident response means preparing your business for a cyber attack or a data leak: a written plan, assigned roles, a way to communicate, an incident register and exercises to check that everyone knows what to do.

Updated on

In Developing your incident response plan (ITSAP.40.003), the Canadian Centre for Cyber Security states that the plan should identify the objectives, stakeholders, responsibilities, communication methods and escalation processes. "Keep the plan simple and flexible. Test, revisit, and revise your incident response plan annually to keep it effective."

Short answer

You describe your business, your systems and what is already in place: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The content of the plan, the roles and the exercises are set with you.

What the quote should cover

  • An inventory of the systems and information that are critical to your operations
  • The likely incident types for your business and the response steps for each
  • Drafting or updating the incident response plan, with roles and backup contacts
  • A communications plan: who reports, who decides, who notifies clients, the insurer or the police
  • A template for the confidentiality incident register that meets the Quebec regulation
  • What the IT services company will do during an incident, and what remains your responsibility
  • At least one exercise to test the plan, followed by a lessons learned document

Prepare before the incident

The Centre recommends starting with a statement of management's commitment and a risk assessment to identify your most valuable assets. The plan is prepared in calm conditions: during an incident, it is too late to look for who has the administrator passwords or the insurer's phone number.

  1. List the systems and information the business cannot do without
  2. Define the likely incidents, such as ransomware, a compromised email account or a lost laptop
  3. Name the response team, with a backup contact for each role
  4. Write the policy and the plan, then have management approve them
  5. Train employees and tell them whom to report an incident to
  6. Test the plan with an exercise and revise it

Roles and communication

According to ITSAP.40.003, the communications plan "should include a central point of contact for employees to report suspected or known incidents." The Centre adds that the response team should have alternate means of contact, such as mobile phones or out-of-band email, since your usual email may be affected.

The baseline cyber security controls call for a written plan that states who is responsible for what, with contact information for external parties, stakeholders and regulators, and for keeping an up-to-date hard copy (BC.1.2). They also suggest considering cyber insurance that covers incident response and recovery (BC.1.3): if you have it, the plan should state when and how to reach the insurer.

The Centre notes that you can handle some actions internally and outsource others to professionals. The quote should therefore state what the IT services company will take on during an incident, under which conditions and how it can be reached, rather than leaving this implicit.

Confidentiality incidents: what Quebec law requires

When an incident involves personal information, the Act respecting the protection of personal information in the private sector applies. The business must take reasonable measures to reduce the risk of injury and to prevent new incidents of the same nature (s. 3.5). Notification is not automatic: "If the incident presents a risk of serious injury," the business must promptly notify the Commission d'accès à l'information and any person whose personal information is concerned (s. 3.5).

To assess that risk, the Act requires considering the sensitivity of the information, the anticipated consequences of its use and the likelihood that it will be used for injurious purposes, and consulting the person in charge of the protection of personal information (s. 3.7). Every incident, even without a risk of serious injury, must be recorded in a register, which the Commission can request (s. 3.8).

The Regulation respecting confidentiality incidents sets out the content of the written notice to the Commission (s. 3), of the notice to the persons concerned (s. 5) and of the register (s. 7), which must include the elements supporting the conclusion as to whether or not there is a risk of serious injury. The plan should therefore state who performs this assessment and how it is documented. For details on these obligations, see our Law 25 guide.

During and after the incident

The Centre describes a lifecycle: preparation, detection and analysis, containment, recovery, then post-incident activities. Containment may require isolating systems and temporarily suspending access. After the incident, the Centre recommends reviewing the root cause and writing a lessons learned document to improve the plan.

For ransomware, the Centre's Ransomware playbook (ITSM.00.099) details the measures to plan for. The plan should point to specific procedures rather than general principles.

Questions to ask yourself before requesting a quote

  • Who is the person in charge of the protection of personal information in your business?
  • Does an employee know today whom to report a suspicious email or a lost computer to?
  • Do you already have a confidentiality incident register?
  • Do you have cyber insurance, and what conditions does it set in case of an incident?
  • Does your current agreement with your IT services company say what it does during an incident?
  • Which activities would you need to maintain even if your systems were unavailable?

Pitfalls to avoid

  • A plan stored only on the server that ransomware could encrypt
  • Believing that every incident must be reported to the Commission, or on the contrary that none need to be recorded
  • Not documenting the assessment of the risk of serious injury
  • A plan that is never tested or updated after a key employee leaves
  • Assuming the IT services company will step in without its obligations being written into the contract

What to specify in your request

  • The size of the business and the number of employees
  • Your critical systems and the types of personal information you hold
  • What already exists: plan, register, policy, cyber insurance
  • Who provides your IT support today
  • Whether you want a simulation exercise, and for which participants
  • Requirements from a client, an insurer or a contract that must be met

You can then describe your project: the team will contact you to clarify your needs and provide a quote.

Frequently asked questions

Must every incident be reported to the Commission d'accès à l'information?

No. Under section 3.5 of the Act, notifying the Commission and the persons concerned is required when the incident presents a risk of serious injury. All incidents must nonetheless be recorded in the register (s. 3.8).

How do you assess the risk of serious injury?

Section 3.7 requires considering the sensitivity of the information concerned, the anticipated consequences of its use and the likelihood that it will be used for injurious purposes. The person in charge of the protection of personal information must be consulted.

What does an incident response plan contain?

According to the Canadian Centre for Cyber Security, the objectives, stakeholders, responsibilities, communication methods and escalation processes. The Centre recommends keeping it simple and flexible.

How often should the plan be tested?

The Centre recommends testing, revisiting and revising the plan annually. It is also wise to review it after a major change, such as a new system or the departure of a key person.

Will my IT services company handle everything?

Not necessarily. The Centre advises determining, for each action, what is done internally and what is outsourced to professionals. The decision to notify the Commission, for example, remains your business's decision. Have each party's role set out in writing.

Incident response

Audits, penetration testing and compliance

Request a quote